fruitbasket/modules/ldap.nix

73 lines
1.5 KiB
Nix
Raw Normal View History

2022-12-17 17:42:10 +01:00
{ config, ... }:
let
# temporary url, zum testen auf laptop zuhause
2022-12-17 19:03:02 +01:00
tld = "de";
hostname = "ifsr";
domain = "auth.staging.${hostname}.${tld}";
portunusUser = "portunus";
portunusGroup = "portunus";
ldapUser = "openldap";
ldapGroup = "openldap";
2022-12-17 17:42:10 +01:00
in
{
users.users."${portunusUser}" = {
isSystemUser = true;
group = "${portunusGroup}";
};
users.groups."${portunusGroup}" = {
name = "${portunusGroup}";
2022-12-17 17:42:10 +01:00
members = [ "${portunusUser}" ];
};
users.users."${ldapUser}" = {
isSystemUser = true;
group = "${ldapGroup}";
};
users.groups."${ldapGroup}" = {
name = "${ldapGroup}";
2022-12-17 17:42:10 +01:00
members = [ "${ldapUser}" ];
};
sops.secrets."portunus_admin" = {
owner = "${portunusUser}";
group = "${portunusGroup}";
};
services.portunus = {
enable = true;
user = "${portunusUser}";
group = "${portunusGroup}";
domain = "${domain}";
ldap = {
user = "${ldapUser}";
group = "${ldapGroup}";
suffix = "dc=${hostname},dc=${tld}";
tls = true;
};
seedPath = "../config/portunus_seeds.json";
};
services.nginx = {
enable = true;
virtualHosts."${config.services.portunus.domain}" = {
forceSSL = true;
enableACME = true;
locations = {
"/".proxyPass = "http://localhost:${toString config.services.portunus.port}";
"/dex".proxyPass = "http://localhost:${toString config.services.portunus.dex.port}";
};
};
};
networking.firewall.allowedTCPPorts = [
80 # http
443 # https
636 # ldaps
];
}